Mind the Bridge - A New Attack Model for Hybrid Mobile Applications
Hack In The Box Security Conference via YouTube
Become an AI & ML Engineer with Cal Poly EPaCE — IBM-Certified Training
Learn Generative AI, Prompt Engineering, and LLMs for Free
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 50% Off
One plan covers every Professional Certificate on Coursera. 50% off Coursera Plus Annual for 10 days only — price increases June 17.
Unlock All Certificates
Explore a groundbreaking attack model for hybrid mobile applications in this conference talk from the Hack In The Box Security Conference. Delve into the world of "Javascript bridges" and uncover a novel class of vulnerabilities in hybrid apps that combine web and native mobile app features. Learn about three vulnerability models that can lead to attacks, bypassing existing validation and restriction technologies. Gain insights into the embedded browser architecture and understand the root cause of these security risks. Discover a new automated tool for vetting hybrid apps and examine a practical mitigation measure called "RichInterface" implemented in a custom embedded browser. Evaluate the effectiveness and scalability of this solution through real-world app examples, presented by an experienced security researcher with expertise in browser and Android application security.
Syllabus
#HITB2021AMS D2T1 - Mind The Bridge: A New Attack Model For Hybird Mobile Applications - Ce Qin
Taught by
Hack In The Box Security Conference